logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2023-1660

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2023-1660

Description:
The AI ChatBot WordPress plugin before 4.4.9 does not have authorisation and CSRF in a function hooked to init, allowing unauthenticated users to update some settings, leading to Stored XSS due to the lack of escaping when outputting them in the admin dashboard
Last updated date:
05/11/2023
Type:
exploit
Confidence:
HIGH
Date of publishing:
05/11/2023
Reference url to background

https://wpscan.com/vulnerability/1a5cbcfc-fa55-433a-a76b-3881b6c4bea2

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy